[Rule Tuning] AWS Route Table Modified or Deleted
leandrojmp opened this issue · comments
Leandro Maciel commented
Link to rule
AWS Route Table Modified or Deleted
Description
This rule looks for the actions:
- ReplaceRoute
- ReplaceRouteTableAssociation
- DeleteRouteTable
- DeleteRoute
- DisassociateRouteTable
With the event.profider
as cloudtrail.amazonaws.com
, but those actions are EC2 actions, so the provider will be ec2.amazonaws.com
.
WIth its currents filter it seems that this rule will never trigger.
Example Data
Current filter with event.provider
as cloudtrail,amazonaws.com